Privacy Policy

  1. Home
  2. / Privacy Policy

Privacy notice pursuant to EU Regulation 2016/679 (GDPR)

ESG Cert S.r.l., with registered office at Via Privata del Gonfalone 3, Milan (MI) 20123, VAT no. IT12063010966 (hereinafter the “Controller”), as Data Controller, informs you, pursuant to EU Regulation 2016/679 (GDPR), that your data will be used in the following ways and for the following purposes.

A. Subject of processing

The Controller processes personal identification data, such as name, surname, email address, and Curriculum Vitae, as well as other data not explicitly requested, communicated by you through the forms on this website or by email.

B. Purposes of processing

The personal data collected will be used:

  1. Without your express consent, as provided for by Article 6 letters b) and e) of the GDPR, for the following purposes:

    1. To conclude contracts for the Controller’s services;
    2. To fulfill pre-contractual, contractual, and tax obligations arising from relationships with you;
    3. To fulfill obligations established by law, regulation, EU legislation, or an order from an Authority;
    4. To exercise the rights of the Controller;
  2. Only with your explicit consent, as provided for by Article 7 of the GDPR, for the following purposes:

    1. To send you newsletters, commercial communications, and/or informational or advertising material about products or services offered by the Controller;
    2. To measure satisfaction with service quality through interviews and/or surveys;
    3. To send you commercial and/or promotional communications by email from third-party partners of the Controller.

C. Methods of processing

Your personal data is processed in accordance with Article 4, paragraph 2 of the GDPR. Your personal data is processed electronically for the time necessary to fulfill the purposes described above and in any case for no more than 5 years from the end of the relationship for service purposes.

D. Access to data

Your data may be made accessible, for the purposes referred to in point B of this notice, to employees and collaborators of the Controller, in their capacity as persons authorized to process data, internal data processors, or system administrators.

E. Disclosure of data

Without the need for express consent, pursuant to Article 6 letters b) and c) of the GDPR, the Controller may disclose your data for the purposes referred to in point B.1 of this notice to Supervisory Bodies, judicial authorities, insurance companies for the provision of insurance services, and all parties to whom disclosure is required by law for the performance of those purposes. These parties will process the data as independent Data Controllers.

Your personal data will not be disseminated.

F. Data transfer

Data is stored within the European Economic Area. If the Controller decides to use third-party providers to process the data you provide, it ensures that the transfer of data is made to providers selected following a careful due diligence process, and that the transfer takes place in accordance with applicable legal provisions, including, where applicable, by entering into the standard contractual clauses provided by the European Commission in the case of transfers to non-EU countries.

G. Nature of data provision and consequences of refusal to respond

The provision of data for the purposes described in point B.1 of this notice is mandatory. Without it, we will not be able to provide you with the services described in point B.1.

The provision of data for the purposes described in point B.2 of this notice is optional. You may therefore decide not to provide any data or subsequently deny permission to process data previously provided. In that case, you will no longer receive newsletters, commercial communications, or advertising material concerning the services offered by the Controller and its partners. In any case, you will continue to be entitled to the services referred to in point B.1.

H. Rights of the data subject

As a data subject, you are guaranteed the rights of access set out in Articles 15-21 of the GDPR, including the right of access, right to rectification, right to erasure (right to be forgotten), right to restriction of processing, right to data portability, right to object, and the right to lodge a complaint with the Supervisory Authority.

I. Exercising rights

You may exercise your rights at any time by sending:

  • a registered letter with return receipt to ESG Cert, Via Privata del Gonfalone 3, Milan (MI) 20123;
  • an email to privacy@esgcert.eu.

J. Data Controller

The Data Controller is ESG Cert S.r.l., with registered office at Via Privata del Gonfalone 3, Milan (MI) 20123, VAT no. IT12063010966